GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,315
Maven
5,000+
npm
3,949
NuGet
711
pip
3,729
Pub
12
RubyGems
920
Rust
965
Swift
38
Unreviewed advisories
All unreviewed
5,000+
313 advisories
Filter by severity
Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a...
Moderate
Unreviewed
CVE-2025-3071
was published
Apr 2, 2025
Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.
High
Unreviewed
CVE-2021-33959
was published
Jan 18, 2023
Ollama DNS rebinding vulnerability
High
CVE-2024-28224
was published
for
github.com/ollama/ollama
(Go)
Apr 8, 2024
A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is...
Moderate
Unreviewed
CVE-2024-45354
was published
Mar 27, 2025
An intent redriction vulnerability exists in the Xiaomi quick App framework application product....
Moderate
Unreviewed
CVE-2024-45353
was published
Mar 27, 2025
An code execution vulnerability exists in the Xiaomi smarthome application product. The...
High
Unreviewed
CVE-2024-45352
was published
Mar 27, 2025
Prefect CORS (Cross-Origin Resource Sharing) misconfiguration
High
CVE-2024-8183
was published
for
prefect
(pip)
Mar 20, 2025
Feast Cross-Origin Resource Sharing vulnerability
High
CVE-2024-11602
was published
for
feast
(pip)
Mar 20, 2025
Inappropriate implementation in in Permission prompts in Google Chrome on Windows prior to 109.0...
Moderate
Unreviewed
CVE-2023-0132
was published
Jan 10, 2023
AgentScope Cross-Origin Resource Sharing (CORS) vulnerability
High
CVE-2024-8487
was published
for
agentscope
(pip)
Mar 20, 2025
A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers to steal sensitive...
High
Unreviewed
CVE-2024-7819
was published
Mar 20, 2025
A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This...
High
Unreviewed
CVE-2024-8024
was published
Mar 20, 2025
Gin mishandles a wildcard at the end of an origin string
Critical
CVE-2019-25211
was published
for
github.com/gin-contrib/cors
(Go)
Jun 29, 2024
An Insufficient Firmware Update Validation vulnerability could allow an authenticated malicious...
Moderate
Unreviewed
CVE-2025-23117
was published
Mar 1, 2025
A CWE-346 "Origin Validation Error" in the CORS configuration in Q-Free MaxTime less than or...
Moderate
Unreviewed
CVE-2025-1102
was published
Feb 12, 2025
esbuild enables any website to send any requests to the development server and read the response
Moderate
GHSA-67mh-4wv8-2f99
was published
for
esbuild
(npm)
Feb 10, 2025
Websites were able to send any requests to the development server and read the response in vite
Moderate
CVE-2025-24010
was published
for
vite
(npm)
Jan 21, 2025
A vulnerability classified as problematic was found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0....
Low
Unreviewed
CVE-2025-1083
was published
Feb 7, 2025
Improper access control in Subscriptions Folder path filter in Devolutions Server 2023.1.1 and...
Moderate
Unreviewed
CVE-2023-2445
was published
May 2, 2023
Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated...
Moderate
Unreviewed
CVE-2023-29868
was published
May 2, 2023
Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker...
Moderate
Unreviewed
CVE-2023-29867
was published
May 2, 2023
This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13...
Moderate
Unreviewed
CVE-2023-27932
was published
May 8, 2023
This issue was addressed with a new entitlement. This issue is fixed in macOS Ventura 13.3, macOS...
High
Unreviewed
CVE-2023-27944
was published
May 8, 2023
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3,...
Moderate
Unreviewed
CVE-2023-27962
was published
May 8, 2023
ProTip!
Advisories are also available from the
GraphQL API